CEH Footprinting and Reconnaissance Practice Question
During an authorized external assessment, a tester wants to determine which mail exchangers and third-party SaaS providers a target uses without alerting the target's security team. The tester already knows the primary domain. Which single command best reveals the target's MX records using a public resolver while sending no traffic to the target itself?
⚠ Common exam trap
The trap here is thinking that any DNS query is passive, when choosing the target's own name server as the resolver still sends traffic to infrastructure the target controls and can monitor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
dig @8.8.8.8 target.com MX +noall +answer
Directing a DNS query to a public resolver such as 8.8.8.8 keeps the request off the target's systems while still returning the MX records needed to identify mail and SaaS providers. The +noall +answer flags trim the output to just the relevant records, making the result easy to parse, and the technique leaves no footprint on target-owned name servers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
dig target.com ANY @target.com
Why it's wrong here
Sending an ANY query to the target's own domain name server contacts target-controlled infrastructure directly, which is active and could be logged or rate-limited. Modern resolvers also frequently refuse ANY queries to mitigate amplification abuse, so the result is unreliable. It fails both the passive requirement and the goal of cleanly isolating MX records.
- ✗
host -t MX target.com 10.0.0.53
Why it's wrong here
This command targets a private RFC 1918 address, which is almost certainly unreachable from the tester's external vantage point and is not a valid public resolver. Even if it resolved, the query would be sent to an internal DNS server, which contradicts the requirement to avoid touching target-owned infrastructure and would likely return no useful answer.
- ✓
dig @8.8.8.8 target.com MX +noall +answer
Why this is correct
This command queries Google's public resolver at 8.8.8.8 for the domain's MX records and displays only the answer section. The DNS request goes to the resolver, not to any hospital-controlled server, so it remains passive relative to the target. The MX records then reveal mail providers and sometimes SaaS tenants, exactly the intelligence required.
- ✗
nslookup -type=MX target.com ns1.target.com
Why it's wrong here
Specifying ns1.target.com as the server directs the query to the target's own authoritative name server. Although the query is small, it still reaches target-owned infrastructure and can be logged, breaking the passive constraint. The MX data returned would be accurate, but the method fails the requirement to avoid alerting the target's security team.
Visual reference
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.